Sr. Technology Compliance Product Owner

Adobe Adobe · Enterprise · San Jose, CA +3

This role is for a Compliance Product Owner within Adobe's Technology GRC group, focusing on continuous auditing and monitoring for compliance functions. It involves performing information security assessments, drafting compliance reports, liaising with external auditors, identifying internal controls issues, contributing to the Common Control Framework, documenting audit procedures, and partnering with GRC Engineering to develop integrations and reports for risk and compliance awareness. The role requires expertise in AI compliance frameworks.

What you'd actually do

  1. Work under the supervision and guidance of the Tech GRC manager and drive technology compliance activities across Adobe.
  2. Perform Information Security related assessments to cover domains like User Access management, Network, OS & Application Security, Encryption, Backup Management, Disaster Recovery, Physical Security, Training & Awareness etc.
  3. Draft compliance reports to summarize the compliance objectives, key findings, and work with teams to remediate key findings
  4. Lead the liaising with external auditors and customers to help them gain comfort with regard to Adobe’s security compliance program.
  5. Identify internal controls issues, ensure they are well-defined and root causes are identified.

Skills

Required

  • Bachelors / master’s Degree with a focus in Information Technology / Computer Science or related field or equivalent work experience
  • Minimum 5-10 years of experience in related field
  • Hand on experience with AWS & Azure environments
  • Knowledge of Compliance frameworks (e.g. BSI C5, Spain ENS, CyberEssentials+, PCI DSS etc.)
  • Expertise with AI compliance frameworks (ISO 42001, NIST AI RMF, CSA AICM etc.)
  • Knowledge of Core IT processes / services such as SDLC, Identity/User Access management, Backup and DR processes will be useful
  • Good interpersonal, verbal and written communication skills.
  • Ability to communicate with both business and IT technical staff including IT and Business management.
  • Ability to look ahead, anticipate questions, independently assess risk, and think critically and creatively

Nice to have

  • Knowledge of Core IT processes / services such as SDLC, Identity/User Access management, Backup and DR processes will be useful

What the JD emphasized

  • Expertise with AI compliance frameworks (ISO 42001, NIST AI RMF, CSA AICM etc.)